Building @buildbuddy (YC W20), ex-Googler

Joined April 2007
96 Photos and videos
Siggi retweeted
Customers kingmake startups. Not VCs.
21
30
281
24,461
Siggi retweeted
Bazel is a superpower
Bazel is seriously underappreciated. Clone of Google’s internal Blaze, it’s cross-language, battle-tested, and extensible. Decades of Google engineering expertise. My favorite part: aggressive caching. I run all tests; it reruns only what changed, tracked by hashes. I’ve never seen it miss a change. 2.5s rebuild test.
1
1
39
6,247
Siggi retweeted
Bazel is seriously underappreciated. Clone of Google’s internal Blaze, it’s cross-language, battle-tested, and extensible. Decades of Google engineering expertise. My favorite part: aggressive caching. I run all tests; it reruns only what changed, tracked by hashes. I’ve never seen it miss a change. 2.5s rebuild test.
29
22
487
47,933
Siggi retweeted
in the an agentic world bazel is a superpower
1
1
17
1,550
Siggi retweeted
Now I understand Bazel more, and it's kinda nice
9
3
57
12,542
Siggi retweeted
Earlier today I leaked AWS credentials to the world; except they weren’t real. This is part of our launch for Honey Tokens (HT) at @infisical - a new class of fake credentials that can be used to trick attackers into thinking that they’ve stolen your real secrets. HTs are useful as decoys for detecting bad actors and breaches in the event that they do happen. Under the hood, HTs are real AWS IAM credentials, except wired up to Infisical, but with zero permissions. When an attacker tries to use a HT, we notify you so you can stay proactive about further securing or rotating your real secrets. In a world where credential breaches are becoming more common, we hope to give you all the tools needed to combat modern security threats. More on this below 👇
We've been going deep cooking up new security infra for agents at @infisical. Dropping a little sneak peek for what's ahead for anyone curious. Excited to show everyone what we've been working on!
19
35
615
144,379
May 4
Incremental builds deserve an incremental cache. Major props to Tyler French from the @buildbuddy team for landing this change in @bazelbuild that reduces cache uploads and disk cache size by 40% buildbuddy.io/blog/content-d…
1
5
12
1,050
Siggi retweeted
For a while, we've been grappling with one big question: How do we give agents secure access to services without them reading any secrets? Today, we provide an early answer: Agent Vault, an open source, HTTP credential proxy and vault. Agents like OpenClaw or Claude Code can proxy requests through Agent Vault regardless of the method an agent uses to interact with any target service: API, CLI, SDK, MCP. With Agent Vault, we’re rethinking how secrets should be consumed by agents. We believe that vaults and/or secret stores are here to stay but the way in which secrets are delivered to fit the ergonomics of how agents operate will change drastically. In the current state, agents cannot be trusted with holding secrets directly and so there has to be a dedicated credential broker beside each agent, be it through a dedicated service, sidecar, or egress layer; to securely attach credentials onto every request to the outside world. With this proxy in place, you can inspect proxied requests and, in the future, apply firewall rules to apply restrictions to traffic flowing through the proxy. The Agent Vault project by @infisical is an early peek into a trend that we believe many folks including Anthropic, Brex, Browser Use and others have caught onto which is the separation of the agent from its credentials. Check it out.
14
19
153
42,976
Siggi retweeted
I am using @bazelbuild to download a Zig nightly build To then build the same Zig version from source (we have patches) Using a custom LLVM source repo Which is also built from source And all of this using remote execution with @buildbuddy.
3
4
23
1,886
Siggi retweeted
Replying to @norootcause
CI is also a bottleneck
2
2
20
2,604
Siggi retweeted
This is so underrated, being able to efficiently have have LLMs part of the build system unblocks a lot of marvels.
Feb 3
Replying to @siggi
Remote caching means you never have to run the same prompt twice (unless an input changes). This saves you tokens and allows you to build complex pipelines of Claude prompts that only get rerun when needed.
1
2
4
295
Siggi retweeted
Replying to @siggi
Exactly ! I show everyone I can how I’m pretty much alone doing codex cloud at this scale just because I don’t care containers are only 2 cores. While every other agents wait minutes doing things locally, mine loop at light speed while everything compiles and test w/ @buildbuddy
3
8
492
Siggi retweeted
Replying to @zeeg @ankrgyl

Replying to @steeve
22 hours 37 minutes done in 6 minutes. You don't need another DSL, you just need better tools.
1
1
5
392
Mar 2
Beyond excited to welcome @SmileyKeith to the BuildBuddy team! Keith is the maintainer of Bazel's iOS support, a contributor to LLVM and Swift, creator of the Mobile Native Foundation, and an all around awesome human. buildbuddy.io/blog/welcoming…
4
11
376
Siggi retweeted
After LLVM, Clang, libc , we now bootstrap Zig from source, too. This is a screenshot of a remote build of the Zig compiler for macOS, built on Linux remote runners.
1
4
59
4,734
Siggi retweeted
22 hours 37 minutes done in 6 minutes. You don't need another DSL, you just need better tools.
2
20
1,570